Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
forti5
New Contributor II

IkeV2 VPN with EntraID SAML

IkeV2 VPN with EntraID SAML

 

All configured and working to a point ! SAML authentication works fine but as soon as I authenticate the connection Immediately drops !

Last Disconnect Reason: HostnameResolveNonRecoverableError

 

Can anyone suggest where to start with troubleshooting this ?

 

I've tried the following but found not errors.

diagnose debug application fnbamd -1

diagnose debug application saml -1

diagnose debug application ike -1

diagnose debug application eap_proxy -1

 

error1.png

 

Dj
Dj
1 Solution
forti5
New Contributor II

now solved. 2 issues.

1. I had to change the default saml setting to - Sign SAML response and assertion

2. In the EMS Remote Access config i had https: , when I should have just had the hostname.

 

saml1.png

 

ras.png

Dj

View solution in original post

Dj
5 REPLIES 5
funkylicious
SuperUser
SuperUser

what version are you running on FortiGate ?

"jack of all trades, master of none"
"jack of all trades, master of none"
forti5
New Contributor II

v7.4.9

Dj
Dj
hpenmetsa
Staff
Staff

Hi,

Does this happen to only one user or to all users?

 

Could you please share the output?

 

diagnose debug reset

diagnose vpn ike log-filter dst-addr4 <client public ip>

diagnose debug app ike -1

diagnose debug app eap_proxy -1

diagnose debug app samld -1

diagnose debug enable

 

replicate the issue connecting to a VPN

AEK
SuperUser
SuperUser

Looks like a DNS issue.

  • Are your DNS queries sent through the tunnel once it is up?
  • Are they served correctly?
  • Is the telemetry server's FQDN resolved with a different address (e.g.: the private IP) once connected?

Try fix these and redo the test.

 
AEK
AEK
forti5
New Contributor II

now solved. 2 issues.

1. I had to change the default saml setting to - Sign SAML response and assertion

2. In the EMS Remote Access config i had https: , when I should have just had the hostname.

 

saml1.png

 

ras.png

Dj
Dj
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors